Skip to main content
Illicit OAuth App-Consent Grant: Entra ID Impersonation Campaign operation cover
COMING SOONIntermediate

Illicit OAuth App-Consent Grant: Entra ID Impersonation Campaign

A mass illicit OAuth app-consent campaign against a maritime logistics tenant. Operators register multitenant Entra apps impersonating trusted SaaS brands (iLSMART, Adobe, DocuSign, OneDrive-2025) and send brand-themed consent lures from compromised supplier accounts. Victims who click are screened by a Tycoon antibot redirector into an adversary-in-the-middle relay that proxies the real Entra sign-in, harvests the password, and intercepts the MFA-approved token. The replayed token completes user-level consent grants to the impersonation apps, which read mailboxes over Microsoft Graph, and the attacker registers a new MFA method for durable persistence. Work the Email lures and the Entra consent, sign-in, Graph, and security-info audit to reconstruct the chain.

40m
7 tasks
50 points
Free

Launches in 2 days

Sep 22, 2026

Tuesday, September 22, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

CloudEmail

What you'll investigate

7 objectives unlock when this operation goes live.

1Incident brief
2Locate the first compromised identity
3Identify the app the analyst consented to
4Expose the impersonation app's true reply URL
5Catch the relay redirector in the lure
6Find the persistence registered on the second victim
7Classify the MFA-bypass technique

Be first when it launches

Create your free account now. The moment this operation goes live on Sep 22, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free